@dariusDarius Kazemi
@glyph like imagine it as a software version of a hardware key like a yubikey. it's a thing which generates a random key for key exchange and authentication, but which tries to make it hard for anybody to grab your device and take the keys out of it. because that would let people trivially clone your passkey / yubikey.
@dotstdyJosh Simmons
@dariusDarius Kazemi
@glyph the things that makes me nervous about passkeys is my poor mental model and my lack of understanding about how to get visibility into what's going on.
My point of comparison is ssh infrastructure.
With ssh I understand (handwavingly) the various key types, how to: use ssh-agent, see what key pairs I have in ~/.ssh/, which pubkey(s) I have uploaded to some service, move keys to a new computer, etc..
Is there a "passkeys for the ssh-comfortable" guide somewhere?
If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/esnyder/statuses/115860859313907921 on your instance and quote it. (Note that quoting is not supported in Mastodon.)